Privacy & data protection

What we hold, and what we don't.

AutoTrip drafts replies inside a business's own inbox. That means guest messages pass through our system — so this page explains exactly who handles them, where they go, and who decides.

Last updated 11 August 2026

Who we are

AutoTrip is a product of Profile for Information Technology and Consulting, a single-person limited liability company registered in Egypt under Investment Law No. 72 of 2017.

Commercial register
300222 — Cairo Investment Registry Office
Tax registration
769-533-264 — Nasr City Third
Licensed activity
6201 — computer programming activities
Registered office
Office N1, 7th floor, 1 Mostafa El-Nahas Street (Abbas El-Akkad intersection), Nasr City, Cairo, Egypt
Data contact
hello@autotrip.cloud

Two different roles — this is the important part

We handle personal data in two distinct capacities, and our obligations differ in each. Most privacy policies blur this. Yours shouldn't have to guess.

Where we are the controller

For people who visit this website or contact us about the product, we decide what is collected and why. That is our data, our responsibility, and the rights described below apply directly against us.

Where we are the processor

For the guest messages flowing through a client's inbox — the emails, WhatsApp messages and reviews written by that business's own customers — the client is the controller and we act only on their documented instructions. We do not own that data, we do not sell it, we do not use it to build products for anyone else, and we do not decide what happens to it. If you are a guest of one of our clients and want your data removed, that request goes to the business you were writing to; we will action it on their instruction.

What we handle

Website visitors

Standard technical data your browser sends — IP address, browser type, pages viewed. We use no advertising or tracking cookies on this site.

People who contact us

If you message us on WhatsApp or by email: your name, your phone number or email address, your business, and whatever you choose to tell us. We keep it to answer you and to follow up about the product.

Client business data

To make the system answer in your voice we hold what you give us: your prices, policies, schedules, past replies, and the rules you set about what may and may not be promised.

Guest conversations

Messages your guests send you, our drafted replies, and your approval decisions. This can include names, contact details, booking details and anything a guest chooses to write — occasionally including health information, such as a guest mentioning a medical condition relevant to an activity. We treat it as sensitive, hold it only to draft replies for you, and never use it for anything else.

Why we're allowed to hold it

Who else touches the data

We use a small number of service providers to run the system. Each is bound by its own contractual data-protection obligations, and none is permitted to use the data for their own purposes.

Anthropic
The AI model that drafts replies. Message content is sent for processing and a draft returns.
United States
Supabase
The database holding business rules, conversation history and approval records.
European Union / United Kingdom
Our cloud hosting provider
Server hosting for the automation layer and this website.
European Union
Meta Platforms
The WhatsApp Business Platform, where a client has connected WhatsApp as a channel.
United States / Ireland
Google
Business Profile reviews, where a client has connected reviews as a channel.
United States / European Union

Some of these sit outside Egypt and outside the European Economic Area. Where that applies we rely on the transfer safeguards those providers offer, including standard contractual clauses.

Access, and who can read your inbox

Access is limited to what running the service requires. In practice that means one named person — the company's sole manager — and no one else. There is no support team, no contractor pool, and no third party browsing client inboxes. Every draft is logged with the approval decision attached, so a client can see what was sent and who allowed it.

How long we keep it

Your rights

Under Egypt's Personal Data Protection Law No. 151 of 2020 and its Executive Regulations, and under the GDPR where it applies to you, you can ask us to: tell you what we hold, correct it, delete it, restrict or object to how we use it, hand it over in a portable format, or withdraw consent you previously gave.

Write to hello@autotrip.cloud and we'll respond within 30 days. If you're a guest of one of our clients, send the request to that business — they decide, and we act on it.

Security

Data is encrypted in transit and at rest with our infrastructure providers. Access is protected by individual credentials and multi-factor authentication. If a breach occurs that puts your rights at risk, we will notify the relevant authority and affected people within the timeframes the law requires.

Children

The service isn't directed at children and we don't knowingly collect their data. A guest message may occasionally mention a child — a family booking, a parent's question about a child's safety. We treat that as sensitive, use it only to draft the reply, and retain it under the same rules as the rest of the conversation.

Changes

If this policy changes materially we'll update the date at the top and, where the change affects clients, tell them directly. Questions about anything here go to hello@autotrip.cloud.